Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-23697—32.6%
——10——CVE-2024-24291—32.6%
——10——CVE-2017-12728—32.6%
——10——CVE-2023-4640—32.6%
——10——CVE-2026-124784.8 MED32.6%
——10The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious WebSocket server can send a crafted unmasked frame with a payload length near UINT64_MAX to trigger an OOB read in a libsoup-based client when max_incoming_payload_size is set to 0.6dCVE-2018-1788—32.6%
——10——CVE-2002-0754—32.6%
——10——CVE-2019-13531—32.6%
——10——CVE-2020-37107—32.6%
——10——CVE-2014-4420—32.6%
——10——CVE-2025-4054—32.6%
——10——CVE-2024-2228—32.6%
——10——CVE-2025-13560—32.6%
——10——CVE-2025-13170—32.6%
——10——CVE-2020-15396—32.6%
——10——CVE-2025-14967—32.6%
——10——CVE-2025-14248—32.6%
——10——CVE-2025-1889—32.6%
——10——CVE-2025-14336—32.6%
——10——CVE-2025-14951—32.6%
——10——CVE-2026-20081—32.6%
——10——CVE-2025-13301—32.6%
——10——CVE-2014-4421—32.6%
——10——CVE-2025-13297—32.6%
——10——CVE-2025-24803—32.6%
——10——CVE-2025-13585—32.6%
——10——CVE-2019-5318—32.6%
——10——CVE-2025-14218—32.6%
——10——CVE-2025-14216—32.6%
——10——CVE-2025-13271—32.6%
——10——CVE-2025-14584—32.6%
——10——CVE-2017-12713—32.6%
——10——CVE-2022-36385—32.6%
——10——CVE-2025-14639—32.6%
——10——CVE-2025-14588—32.6%
——10——CVE-2026-429695.5 MED32.6%
——10Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.61dCVE-2020-13472—32.6%
——10——CVE-2025-14621—32.6%
——10——CVE-2025-14647—32.6%
——10——CVE-2025-14644—32.6%
——10——